1. Privacy at a glance
INNOVERSIL develops software, artificial-intelligence and Adaptive Intelligence systems, including Zecleo.
Subject to this Notice, applicable law and relevant customer agreements:
- Eligible Customer Content and Service Data may be processed to operate, personalise, evaluate, train, test, secure and improve Zecleo and other INNOVERSIL systems.
- Adaptive Intelligence processing is an essential part of the standard Zecleo service.
- The standard service does not provide a separate individual AI-training opt-in.
- Users who do not agree with the processing model should not use the affected service.
- Mandatory privacy rights remain available where applicable.
- Restricted credentials, payment information, private keys, information known to concern children and other prohibited information are excluded from general shared-model training.
- Written enterprise agreements may provide additional restrictions or processing configurations.
2. Who we are
INNOVERSIL (Pty) Ltd is a South African software technology company that develops and operates Zecleo and other software, artificial-intelligence and adaptive-technology services.
References to INNOVERSIL, we, us or our mean INNOVERSIL (Pty) Ltd and, where relevant, entities operating under its control.
Registered and principal address:
Spaces Design Quarter
Leslie Avenue, Fourways
Sandton, 2055
South Africa
3. Our privacy roles
3.1 When INNOVERSIL is the responsible party or controller
INNOVERSIL acts as the responsible party or controller when it determines why and how personal information is processed.
This generally includes processing involving:
- Visitors to innoversil.com and zecleo.com.
- Prospective customers and direct customers.
- Account registration and administration.
- Billing, subscriptions and commercial relationships.
- Security, fraud prevention and compliance.
- Marketing and professional communications.
- INNOVERSIL research and product development.
- Service Data used for analytics and improvement.
- Eligible information used to develop Shared Intelligence.
- Suppliers, advisers and business partners.
3.2 When INNOVERSIL acts for a customer
Where an organisation uses Zecleo or another INNOVERSIL service to process personal information for that organisation's purposes, the organisation generally acts as the responsible party or controller and INNOVERSIL acts as its operator or processor.
In those circumstances:
- The customer determines why the information is processed.
- INNOVERSIL processes the information to provide the contracted service.
- The customer is responsible for its notices, permissions and lawful authority.
- Requests concerning customer-controlled information should generally be directed to that customer.
- INNOVERSIL will assist the customer where required by law or contract.
3.3 Shared AI training
Where INNOVERSIL uses eligible Customer Content or Service Data for shared-model training, general product improvement or its own AI-development purposes, INNOVERSIL may act as a separate or independent responsible party or controller for that use.
Privacy roles may be further defined in product terms, data-processing agreements, enterprise agreements and service-specific notices.
4. Scope of this Notice
This Notice applies to information processed through:
- innoversil.com, zecleo.com and related websites, subdomains and forms.
- Zecleo and other INNOVERSIL software products and cloud services.
- Product demonstrations, trials and account-registration processes.
- AI development, training, testing, evaluation and operation.
- Advisory, consulting, implementation and technology services.
- Customer support and professional communications.
- Relationships with customers, users, suppliers, advisers and partners.
- Integrations and connected services authorised by users or customers.
This Notice does not govern:
- Information processed solely under a customer organisation's privacy notice.
- Employee or recruitment information governed by a separate notice.
- Third-party services not controlled by INNOVERSIL.
- Processing governed by a more specific product notice or written agreement.
5. Definitions
5.1 Personal information
Personal information or personal data means information relating to an identified or reasonably identifiable person and, where applicable under South African law, an identifiable juristic person.
5.2 Customer Content
Customer Content means content submitted, uploaded, created, generated, stored or transmitted through an INNOVERSIL service.
It may include:
- Documents, files and spreadsheets.
- Prompts and instructions.
- Messages, comments and discussions.
- Images, audio and video.
- Reports, calculations and presentations.
- Generated responses and analyses.
- Corrections, ratings and feedback.
- Connected-service content.
- Business and professional information.
5.3 Service Data
Service Data means information generated through the operation, security, configuration and use of an INNOVERSIL service.
It may include:
- Feature usage and interaction sequences.
- System events and diagnostic information.
- Device and browser information.
- Error and performance information.
- Security and misuse signals.
- Account configuration.
- Model-performance information.
Service Data may remain personal information where it can reasonably be connected to a person or account.
5.4 Adaptive Intelligence
Adaptive Intelligence means INNOVERSIL technology designed to understand context, identify patterns, personalise assistance, improve recommendations and adapt services over time.
5.5 Account-Specific Intelligence
Account-Specific Intelligence means intelligence, memory, indexes, configurations or adaptations intended primarily for a particular user, organisation, department, project or approved context.
5.6 Shared Intelligence
Shared Intelligence means models, systems and capabilities that may benefit multiple users, accounts or customers.
5.7 Training Data
Training Data means information used to train, fine-tune, adapt, evaluate, test, validate, benchmark, secure or improve an AI model or AI-enabled system.
5.8 De-identified information
De-identified information means information from which direct identifiers have been removed, changed or reduced.
INNOVERSIL does not describe information as anonymous unless individuals are no longer reasonably identifiable.
6. Information we collect
6.1 Identity and contact information
This may include names, titles, email addresses, telephone numbers, business or postal addresses, country, preferred language, usernames and profile information.
6.2 Organisation and professional information
This may include employer, organisation, job title, department, professional role, industry, qualifications, expertise and business or tax information.
6.3 Account and authentication information
This may include account identifiers, usernames, password hashes, multifactor-authentication records, single sign-on identifiers, sessions, login history, permissions and authorised integration credentials.
Passwords, private authentication secrets, complete API keys and complete access tokens are not eligible for general shared-model training.
6.4 Customer Content and AI interactions
This may include documents, prompts, conversations, messages, generated outputs, user corrections, feedback, workflow activity and information obtained through enabled integrations.
Customer Content may contain personal, confidential or sensitive information. Users and customer organisations should submit only information that they are authorised to provide.
6.5 Usage and technical information
This may include IP address, approximate location inferred from IP, device and browser type, operating system, language, time zone, pages and features used, session duration, interaction sequences, errors, performance and diagnostic information.
6.6 Billing and transaction information
This may include billing contacts, billing addresses, subscriptions, invoices, payment status, transaction history and limited payment-method information.
Complete payment-card details may be processed by authorised payment providers.
6.7 Communications and support
This may include enquiries, consultations, support tickets, correspondence, meeting notes, complaints, disputes and call recordings where lawful notice has been provided.
6.8 Marketing information
This may include communication preferences, consent and objection records, campaign interactions, event attendance, professional interests and newsletter engagement.
6.9 Security and compliance information
This may include suspected misuse, fraud indicators, security alerts, access records, investigations, incident records and regulatory correspondence.
7. How information is collected
Information may be collected:
- Directly when a user creates an account, submits content, enters a prompt, contacts support or makes a payment.
- From employers, customer organisations and account administrators.
- Through cookies, application events, logs, APIs, monitoring and diagnostic systems.
- From connected services where a user or customer enables an integration.
- From payment, identity, infrastructure and professional service providers.
- From public professional, corporate or regulatory sources where lawful.
- From licensed or otherwise lawfully obtained datasets.
8. Purposes and lawful bases
8.1 Providing products and services
We process information to create and operate accounts, provide features, execute prompts, process Customer Content, generate outputs, provide integrations and deliver professional services.
The legal basis may include contract performance, steps requested before entering a contract or another lawful basis.
8.2 Account-Specific Intelligence
We may process information to understand context, preserve permitted memory, personalise recommendations, adapt interfaces, support retrieval and improve assistance within an account.
8.3 Shared Adaptive Intelligence
We may process eligible information to train shared models, improve general capabilities, evaluate response quality, develop features, improve reliability and reduce harmful or unreliable outputs.
The legal basis may include:
- Contract performance where processing is objectively intrinsic to the requested service.
- INNOVERSIL's legitimate interests in developing, operating, securing and improving its services.
- Customers' and users' legitimate interests in receiving useful and reliable Adaptive Intelligence.
- Consent where applicable law requires consent.
- Another lawful basis recognised by applicable law.
8.4 Security and fraud prevention
Information may be processed to authenticate users, prevent fraud, investigate misuse, enforce permissions, protect systems and respond to incidents.
8.5 Analytics and improvement
Service Data, feedback and de-identified information may be used to understand product use, identify errors, improve usability, plan capacity and develop products.
8.6 Billing and administration
Information may be processed to issue invoices, collect payments, manage subscriptions, maintain records and comply with tax and accounting obligations.
8.7 Marketing
Contact and preference information may be used to provide requested communications, product information, invitations and permitted professional marketing.
Electronic direct marketing will be based on consent or an applicable existing-customer exception where permitted by law.
8.8 Legal and corporate purposes
Information may be processed to comply with law, respond to lawful requests, establish or defend claims, enforce agreements and conduct investment, financing, restructuring or corporate transactions.
9. AI and Adaptive Intelligence
Eligible Customer Content and Service Data may be used to operate, personalise, evaluate, train, test, secure and improve Zecleo and other INNOVERSIL systems.
Users who do not accept this processing model should not use Zecleo and should cease using the affected service.
9.1 Essential processing
Zecleo is designed to understand eligible user context, learn from interactions, improve recommendations and develop more effective assistance over time.
Adaptive processing, personalisation, training, evaluation, testing, safety and model improvement are essential elements of the standard Zecleo service.
9.2 No separate standard training opt-in
INNOVERSIL does not provide a separate individual opt-in before eligible information is processed for the Adaptive Intelligence purposes described in this Notice.
The standard service is designed on the basis that eligible information may be used to operate and improve Adaptive Intelligence.
This does not convert continued use into consent where applicable law requires an affirmative act. INNOVERSIL must still establish an applicable lawful basis.
Where local law requires prior consent and no other lawful basis is available, INNOVERSIL may request the legally required permission or decline, suspend or limit the affected feature or service.
9.3 Information that may be used
Eligible information may include:
- Prompts and instructions.
- Generated outputs and responses.
- User corrections, ratings and feedback.
- Documents or relevant document excerpts.
- Messages and workflow activity.
- Interaction sequences and preference signals.
- Feature-use and account-configuration information.
- Model-performance and diagnostic information.
- Safety and misuse signals.
- Information supplied through authorised integrations.
- Other Customer Content or Service Data relevant to Adaptive Intelligence.
Not every item will be selected for training. Information may be sampled, filtered, transformed, pseudonymised, de-identified, aggregated, minimised or excluded.
9.4 Account-Specific Intelligence
Customer Content may be used to adapt Zecleo to a particular user, account, organisation, department, project or professional context.
This may include:
- Private or account-specific memory.
- User and organisation preferences.
- Account-specific indexes.
- Organisational knowledge.
- Workflow adaptation.
- Recurring patterns and recommendations.
- Retrieval systems and specialised model adapters.
9.5 Shared Intelligence
Eligible Customer Content and Service Data may be used to improve systems and capabilities that benefit users or customers beyond the originating account.
Shared training may learn from:
- Common task and workflow patterns.
- Successful and unsuccessful responses.
- User corrections and feedback.
- De-identified examples.
- Model-performance information.
- Safety testing.
- Feature-use patterns.
9.6 Legitimate-interest assessment
Where legitimate interests are relied upon for AI training, INNOVERSIL will assess:
- The specific interest being pursued.
- Whether processing contributes to that interest.
- Whether the processing is reasonably necessary.
- Whether a less intrusive alternative is reasonably available.
- The amount and sensitivity of information.
- The context in which the information was collected.
- Users' reasonable expectations.
- Potential effects on individuals.
- Safeguards that reduce those effects.
- Whether an individual's rights override the identified interests.
9.7 Information excluded from general shared training
The following information will not knowingly be selected for general shared-model training unless a separate lawful and specifically approved arrangement applies:
- Passwords and authentication secrets.
- Private encryption keys.
- Complete API keys or access tokens.
- Complete payment-card information.
- Bank-login credentials.
- Government-issued identity numbers.
- Information known to concern children.
- Material known to be protected by legal professional privilege.
- Information prohibited from training by law.
- Information expressly excluded under a written customer agreement.
Automated and manual filtering may be used, but no filtering method can guarantee detection of every prohibited item.
Users must not deliberately submit passwords, payment credentials, private keys or similarly restricted information.
9.8 Sensitive information
Customer Content may contain sensitive or special-category information.
INNOVERSIL does not rely solely on ordinary legitimate interests where an additional legal condition is required.
Where sensitive information is detected, INNOVERSIL may:
- Exclude it from general training.
- Redact or transform it.
- De-identify or minimise it.
- Restrict access.
- Delete it from active training datasets.
- Suspend the affected processing.
- Require the user or customer to remove it.
9.9 Organisational accounts
An employer, business, educational institution or other organisation providing access to Zecleo is responsible for:
- Having authority to submit the relevant information.
- Providing required notices.
- Identifying its lawful basis.
- Complying with employment, confidentiality and sectoral obligations.
- Managing account permissions.
- Communicating contractual restrictions to INNOVERSIL.
9.10 Enterprise configurations
A written enterprise agreement may provide additional configurations, such as:
- Restrictions on Shared Intelligence training.
- Dedicated or isolated processing.
- Private indexes.
- Account-specific adaptation.
- Additional audit information.
- Special retention or deletion requirements.
9.11 External AI providers
INNOVERSIL may use authorised providers for model hosting, inference, training infrastructure, evaluation, safety testing, storage, computing and security.
Those providers may process eligible prompts, Customer Content, outputs, Service Data, diagnostic information and safety information.
Their permitted processing depends on the applicable contract, provider terms, product configuration and INNOVERSIL instructions.
Where an external provider is permitted to use submitted information for its own training, INNOVERSIL will disclose that material practice through an applicable notice, product documentation or Subprocessor List.
9.12 Human review
Authorised personnel or contracted reviewers may review limited information for:
- Model evaluation and quality assurance.
- Error investigation.
- Safety analysis and misuse prevention.
- Product improvement.
- Customer support.
- Review of reported problems and user feedback.
Access will be limited according to role, purpose and need, and reviewers will be subject to confidentiality and security obligations.
9.13 AI-output limitations
AI outputs are probabilistic and may be:
- Inaccurate.
- Incomplete.
- Outdated.
- Biased.
- Misleading.
- Unsuitable for a particular purpose.
Users must apply appropriate human judgement, particularly for legal, medical, financial, taxation, employment, education, safety and other high-impact decisions.
9.14 Automated decisions
General Zecleo assistance is not intended to make solely automated decisions producing legal or similarly significant effects without appropriate safeguards.
Where a service is used for a legally significant decision, applicable safeguards may include notice, meaningful information, human oversight, review, correction and an applicable challenge or appeal process.
9.15 Objections
Where applicable law provides a right to object, an individual may email:
info@innoversil.com
Subject: Adaptive Intelligence Processing Objection
Depending on the circumstances, INNOVERSIL may:
- Stop adding future information to a specified active training dataset.
- Suppress or remove eligible active-dataset records.
- Restrict a processing activity.
- Continue processing where compelling lawful grounds apply.
- Retain information required for security, legal compliance or claims.
- Suspend or close an account where the restriction makes the service impossible to provide.
Suspension or closure is not intended as retaliation. It may be necessary where Zecleo cannot operate in its intended adaptive form without the restricted processing.
9.16 Account closure
Users who do not accept the Adaptive Intelligence model should stop using Zecleo and close their accounts.
After closure:
- New information will no longer be collected through ordinary account use.
- Active Customer Content will be handled according to the applicable retention schedule.
- Certain information may be retained for legal, security, billing or dispute purposes.
- Information may remain temporarily in secured backups.
- Properly anonymous information may continue to be retained.
- Completed model training will not automatically be reversed.
9.17 Completed model training
AI training changes statistical parameters and relationships within a model. It may not always be technically possible to isolate or reverse the effect of one particular interaction after training is complete.
Where a valid legal request applies, reasonable and proportionate measures may include:
- Deleting source records.
- Removing records from active training datasets.
- Preventing future use.
- Suppressing identified records.
- Removing information from retrieval or memory systems.
- Corrective fine-tuning.
- Model replacement or retraining.
- Output filtering.
INNOVERSIL will not state that information has been removed from a trained model unless that result has been reasonably verified.
9.18 Material changes
Where a change materially expands the categories of personal information used, the purposes of training or the parties receiving information, INNOVERSIL will update this Notice and provide any additional notice or control required by applicable law.
11. Sale, sharing and advertising
INNOVERSIL does not sell Customer Content in exchange for money.
INNOVERSIL does not use Customer Content to deliver third-party behavioural advertising.
Website identifiers, device information or online activity may be disclosed to analytics or advertising providers where those technologies are enabled.
Where applicable law treats a disclosure as a sale, sharing, targeted advertising or cross-context behavioural advertising, INNOVERSIL will provide legally required notices and controls.
12. International transfers
INNOVERSIL is based in South Africa and may use infrastructure, providers or personnel in other countries.
Where required, an appropriate transfer mechanism will be used, which may include:
- A legally recognised adequacy determination.
- Contractual data-protection clauses.
- European Commission Standard Contractual Clauses.
- The United Kingdom International Data Transfer Agreement.
- The United Kingdom Addendum.
- Binding organisational safeguards.
- Legally valid consent.
- Contractual necessity.
- Another legally permitted exception.
The applicable mechanism depends on the origin, destination, recipient, information and processing purpose.
13. Retention
INNOVERSIL retains information only for as long as reasonably necessary for its purpose, subject to legal, contractual, security, technical and dispute requirements.
13.1 Enquiries and prospects
Ordinarily retained for up to 24 months after the last meaningful interaction unless a longer period is justified.
13.2 Customer and contractual records
Ordinarily retained for the contract term and up to seven years afterwards where required for tax, accounting, audits, claims or statutory recordkeeping.
13.3 Account information
Retained while the account is active and for a limited period after closure. Certain records may be retained longer for billing, security, fraud prevention, compliance or disputes.
13.4 Customer Content
Retained according to customer settings, account configuration, deletion actions, administrator instructions, applicable agreements, legal holds and backup cycles.
13.5 Support information
Ordinarily retained for up to three years after closure unless associated with a contract, security incident, litigation, complaint or legal obligation.
13.6 Security information
Routine security and diagnostic records may be retained from approximately 30 days to 24 months depending on risk, purpose, investigation and contractual obligations.
13.7 AI Training Data
Information selected for an active training dataset is retained only as long as reasonably necessary for the relevant training, evaluation, validation, safety, reproducibility or audit purpose.
Model versions, parameters and evaluation records may be retained for the operational life of a model and for a reasonable period afterwards for safety, auditing, investigation, reproducibility or legal compliance.
13.8 Marketing suppression records
Minimal information may be retained for as long as needed to ensure an objection or unsubscribe request remains effective.
13.9 Backups
Deleted information may remain temporarily in secured backups until removed through the ordinary backup cycle.
14. Privacy rights
Depending on applicable law, individuals may have the right to:
- Receive information about processing.
- Request access to personal information.
- Request correction of inaccurate information.
- Request completion of incomplete information.
- Request deletion.
- Request restriction.
- Object to processing.
- Object to direct marketing.
- Withdraw consent where consent is used.
- Receive portable information.
- Opt out of sale, sharing or targeted advertising.
- Limit specified uses of sensitive personal information.
- Challenge specified automated decisions.
- Request appropriate human review.
- Use an authorised agent where permitted.
- Appeal a denied request where applicable.
- Complain to a privacy regulator.
- Exercise rights without unlawful discrimination.
Rights are subject to applicable exemptions, verification requirements, legal obligations and overriding lawful grounds.
14.1 Submitting a request
Requests may be emailed to info@innoversil.com.
A request should identify:
- The requester.
- The relevant account or organisation.
- The relevant product or service.
- The right being exercised.
- The information concerned.
INNOVERSIL may verify identity before completing a request.
Where INNOVERSIL acts as a processor, the request may be directed to the relevant customer organisation.
Requests will be handled within the time required by applicable law.
15. Regional privacy information
15.1 South Africa
Where the Protection of Personal Information Act applies, individuals may have rights relating to notification, access, correction, deletion, objection, direct marketing, specified automated decisions, security-compromise notices and complaints.
Complaints may be submitted to the Information Regulator South Africa through its official website:
15.2 European Economic Area
Where the General Data Protection Regulation applies, individuals may have rights of access, correction, deletion, restriction, objection, portability, consent withdrawal, protection concerning specified automated decisions and complaint to a supervisory authority.
15.3 United Kingdom
Where United Kingdom privacy law applies, equivalent rights may be exercised under the UK GDPR and Data Protection Act. Complaints may be submitted to the Information Commissioner's Office.
15.4 United States
This section applies only where INNOVERSIL and the relevant processing fall within an applicable United States privacy law.
Depending on the jurisdiction, residents may have rights to:
- Know, access, delete or correct information.
- Receive portable information.
- Opt out of sale, sharing or targeted advertising.
- Limit specified sensitive-information processing.
- Opt out of specified profiling or automated decisions.
- Use an authorised agent.
- Appeal a denied request.
INNOVERSIL does not sell Customer Content for monetary consideration.
15.5 Brazil
Where Brazil's LGPD applies, individuals may have rights concerning confirmation, access, correction, deletion, anonymisation, blocking, portability, recipients, consent withdrawal and review of specified automated decisions.
15.6 Canada
Where Canadian privacy law applies, INNOVERSIL will observe applicable requirements concerning lawful authority, transparency, reasonable purposes, safeguards, access, correction and accountability.
15.7 Australia
Where Australian privacy law applies, personal information used as AI input, output or Training Data remains subject to applicable privacy requirements.
15.8 Other jurisdictions
INNOVERSIL will honour mandatory rights under other applicable privacy laws even where they are not expressly listed in this Notice.
17. Security and incidents
17.1 Security safeguards
INNOVERSIL maintains technical and organisational safeguards designed to protect personal information.
Depending on the service, measures may include:
- Identity and access controls.
- Least-privilege permissions.
- Authentication safeguards.
- Multifactor authentication.
- Encryption.
- Logging and monitoring.
- Environment separation.
- Secure development practices.
- Vulnerability management.
- Backup protections.
- Incident-response procedures.
- Personnel confidentiality.
- Supplier assessment.
- Security testing.
Specific safeguards vary according to the service, deployment, risk, processing purpose and applicable agreement.
No electronic service is completely secure. INNOVERSIL cannot guarantee that unauthorised access, loss, misuse or disruption will never occur.
17.2 Security incidents
Where INNOVERSIL becomes aware of a security incident involving personal information, it will take reasonable steps to:
- Investigate the incident.
- Contain the incident.
- Assess its scope and potential harm.
- Preserve appropriate evidence.
- Remediate affected systems.
- Notify customers, individuals or regulators where legally required.
- Take reasonable steps to reduce recurrence.
18. Children
INNOVERSIL's general business services are not directed to children.
A person may not independently create a standard account unless the person is at least 18 years old or validly authorised under a specific guardian, family, education or institutional arrangement.
Information known to concern children will not knowingly be selected for general shared-model training.
Where INNOVERSIL offers an education-specific or child-directed service, it may provide a separate notice, age-appropriate information, required authorisation, restricted processing and additional safety controls.
Child privacy concerns may be sent to info@innoversil.com.
19. Third-party services
INNOVERSIL services may link to or integrate with third-party services.
INNOVERSIL is not responsible for an independent third party's privacy practices.
Users should review the third party's privacy notice, permissions, retention, AI-training and security terms.
Where a third party acts as an INNOVERSIL processor, its processing will be governed by the applicable agreement with INNOVERSIL.
20. Changes to this Notice
INNOVERSIL may update this Notice to reflect changes in law, products, AI models, training practices, providers, technology, security, privacy controls or business operations.
The Last updated date will be revised.
Where legally required, material changes may be communicated through email, a website notice, an in-product notice, an account notification or updated contractual documentation.
Where a change materially expands the use of personal information for AI training, INNOVERSIL will provide any additional notice or control required by applicable law.
Earlier versions may be requested from info@innoversil.com.
21. Contact and complaints
Questions, objections, complaints and privacy requests may be directed to:
Attention: Information Officer / Privacy Team
Spaces Design Quarter
Leslie Avenue, Fourways
Sandton, 2055
South Africa
Email: info@innoversil.com
Websites:
innoversil.com
zecleo.com
This Notice describes INNOVERSIL's privacy practices. It does not limit rights or obligations imposed by applicable law.
